Whonix KVM dnsmasq - listen port on host operating system - attack surface reduction

Could you try please using <dns enable="no"/> for the default network (and any other networks you may have)?

sudo virsh net-edit default

Then try:

sudo apt purge dnsmasq

Maybe that way we can completely get rid of dnsmasq?

Or libvirt will still crash due to:

This would initially break DNS inside any non-Whonix VMs. That could be fixed by using a public DNS resolver.